| Scenario | MIT01 Validate |
MIT02 Provenance |
MIT03 Access Ctrl |
MIT04 TTL |
MIT05 Human Review |
MIT06 Tier Sep. |
MIT07 Reduced Trust |
MIT08 Audit Log |
MIT09 Integrity |
|---|---|---|---|---|---|---|---|---|---|
| S1: Poisoned support knowledge base (insider) | ● | ● | ● | · | ● | ● | ● | ● | ● |
| S2: Malicious PDF poisons preference store | ● | ● | ● | ● | ● | · | ● | ● | ● |
| S3: Cross-tenant memory leakage via query | · | ● | ● | · | · | · | · | ● | · |
| S4: Multi-agent cascade via shared memory write | ● | ● | ● | ● | · | ● | ● | ● | ● |
| S5: Session memory → standing false policy | ● | ● | ● | ● | ● | · | ● | ● | ● |
| S6: Email ingestion plants payment redirect | ● | ● | ● | ● | ● | ● | ● | ● | ● |
MIT03 (Access Controls) is the primary control for three scenarios and contributes to all six. MIT06 (Tier Separation) is the only control that fully prevents the S1 and S4 attack classes where write access is granted to a legitimate channel. S3 (cross-tenant leakage) is uniquely isolated: MIT03 alone is the primary defense — no other mitigation addresses the read-side extraction path directly.